Privacy Policy

Last updated: 14 September 2026

Who we are

TotalAudits is a trading name of Nomad Optimise Ltd, a company registered in England and Wales.

Registered office: St James' Hall, Mill Road, Lancing, West Sussex, BN15 0PT Company number: 15235771 ICO registration: ZB807103

We are the data controller for personal data collected through totalaudits.io.

If you have questions about this policy or about how we handle your data, contact us at chandler@totalaudits.io.

What this policy covers

This policy explains what personal data we collect when you use totalaudits.io, why we collect it, what we do with it, and what rights you have over it. It applies to visitors to our website and to customers who subscribe to our services.

What we collect

Information you give us directly

  • Name and business name
  • Email address
  • Billing address and bank details for Direct Debit
  • The website address you want audited
  • Any information you include in messages you send us

Information we collect automatically

  • IP address
  • Browser type and version
  • Device type and operating system
  • Pages viewed, time spent, and how you arrived at our site
  • Cookie, pixel and behaviour-analytics data, including recordings of how you interact with our pages (see our Cookie Policy)

Information from your website

When you subscribe to an audit, we collect publicly available technical and content data about the website you ask us to audit. Where you grant us access to third-party tools such as Google Search Console or Google Analytics, we access the data those tools hold about your site. We only access accounts you have explicitly granted us permission to access, and only for the purpose of delivering your audit.

Payment information

Payments are taken by Direct Debit and processed by Stripe. We do not store your full bank details. Stripe handles that information under its own privacy policy. We receive confirmation of payment, a partial account reference, and billing details.

Why we use it, and our lawful basis

What we use it for Lawful basis
Delivering the audit you have subscribed to Performance of a contract
Taking payment and managing your subscription Performance of a contract
Responding to enquiries Legitimate interests — responding to people who contact us
Sending service emails about your subscription Performance of a contract
Sending marketing emails Consent, or legitimate interests where you are an existing customer
Understanding how our website is used Consent (via cookie banner)
Advertising and measuring ad performance Consent (via cookie banner)
Meeting legal and accounting obligations Legal obligation
Preventing fraud and securing our systems Legitimate interests — protecting our business
Recovering unpaid fees Legitimate interests — recovering money owed to us

Who we share it with

We share personal data with service providers who help us operate. Each acts on our instructions under a contract that restricts what they can do with it:

  • Stripe — payment and Direct Debit processing
  • Google (Google Workspace) — email and business productivity
  • Webflow — website hosting
  • Cloudflare — content delivery, security and bot management
  • Google Analytics — website analytics
  • Hotjar — website behaviour analytics, where you have accepted analytics cookies
  • YouTube (Google) — embedded video on our website
  • Google Ads — advertising and conversion measurement, where you have accepted advertisement cookies
  • Meta Platforms — advertising and conversion measurement, where you have accepted advertisement cookies
  • LinkedIn — advertising and conversion measurement, where you have accepted advertisement cookies
  • PJCO (Peter Jarman LLP) — accountancy and bookkeeping
  • SEO and analytics tools used to produce your audit

We may also disclose personal data where we are required to by law, or to establish, exercise or defend legal claims.

We do not sell your personal data.

Advertising and behaviour analytics

We use the Meta pixel, the LinkedIn Insight Tag and Google advertising tags on totalaudits.io. These only load if you accept advertisement cookies.

When active, they send information about your visit — including your IP address and the pages you viewed — to Meta, LinkedIn and Google. Those companies may combine that information with data they already hold about you, and may use it for their own purposes as set out in their own privacy policies. For some of this processing we and those platforms act as joint controllers.

We also use Hotjar, which records how visitors interact with our pages — clicks, scrolling and navigation — to help us improve the site. Hotjar only loads if you accept analytics cookies.

Our site embeds YouTube video, which sets cookies when you accept functional or analytics cookies.

You can withdraw consent at any time through the cookie settings link in our website footer, and you can manage your advertising preferences directly with Google, Meta and LinkedIn through their own account settings.

International transfers

Several of our service providers — including Stripe, Google, Webflow, Cloudflare, Hotjar, Meta and LinkedIn — are based in or transfer data to the United States. Where personal data is transferred outside the UK, we rely on either an adequacy decision by the UK government (including the UK Extension to the EU-US Data Privacy Framework where the recipient is certified), or the International Data Transfer Agreement or Addendum, to ensure your data receives equivalent protection.

How long we keep it

  • Customer records and audit deliverables: for the duration of your subscription and for six years afterwards, to meet accounting and legal requirements
  • Data accessed from your analytics accounts: deleted at the end of your subscription
  • Enquiries that do not become customers: two years from last contact
  • Marketing contacts: until you unsubscribe, then we keep a suppression record so we do not contact you again
  • Website analytics and advertising data: as set out in our Cookie Policy

Your rights

Under UK data protection law you have the right to:

  • Access — ask for a copy of the personal data we hold about you
  • Rectification — ask us to correct data that is wrong or incomplete
  • Erasure — ask us to delete your data, where we have no overriding reason to keep it
  • Restriction — ask us to limit how we use your data
  • Portability — ask for your data in a portable format, or ask us to send it to another provider
  • Object — object to us processing your data on the basis of legitimate interests, or for direct marketing
  • Withdraw consent — where we rely on consent, withdraw it at any time

To exercise any of these, email chandler@totalaudits.io. We will respond within one month.

If you are not satisfied with our response, you can complain to the Information Commissioner's Office at ico.org.uk, or by calling 0303 123 1113.

Security

We use appropriate technical and organisational measures to protect your data, including encrypted connections, access controls, and limiting access to those who need it. No system is completely secure, but we take our obligations seriously and review our arrangements regularly.

Automated decision-making

We do not make decisions about you based solely on automated processing that have legal or similarly significant effects.

Children

Our services are for businesses. We do not knowingly collect personal data from anyone under 18.

Changes to this policy

We may update this policy from time to time. The date at the top shows when it was last changed. Where changes are significant, we will tell you by email or through a notice on the site.